CVE-2019-16695: SQL Injection
Published Sep 22, 2019
·Updated
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
Affected Software
1 affected component
Phpipam Phpipam<=1.4
Event History
Sep 22, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16695?
CVE-2019-16695 is a vulnerability in phpIPAM 1.4 that allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
2
How severe is CVE-2019-16695?
CVE-2019-16695 has a severity rating of 9.8 (critical).
3
How does CVE-2019-16695 affect phpIPAM?
CVE-2019-16695 affects phpIPAM version 1.4.
4
How can I fix CVE-2019-16695?
To fix CVE-2019-16695, update phpIPAM to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2019-16695?
More information about CVE-2019-16695 can be found at the following link: [Reference Link](https://github.com/phpipam/phpipam/issues/2738)